An organization is updating its enterprise risk management framework and classifying its existing defense mechanisms according to CompTIA Security+ control categories. The Chief Information Security Officer (CISO) requests an inventory of all Managerial (Administrative) controls currently implemented across the company. Which of the following defense mechanisms qualify as Managerial controls? (Select TWO.)
- Performing annual third-party vendor risk assessments to evaluate supply chain security risksAnswer
- Establishing an enterprise-wide Acceptable Use Policy (AUP) approved by executive managementAnswer
- CConfiguring Next-Generation Firewalls (NGFW) to inspect and block malicious ingress traffic
- DConducting daily physical perimeter security patrols around the data center facility by hired security guards
Answer
Performing annual third-party vendor risk assessments and establishing an enterprise-wide Acceptable Use Policy (AUP) are both Managerial controls.
Both vendor risk assessments and acceptable use policies focus on governance, administrative oversight, and risk strategy. Under CompTIA Security+, controls designed around management decisions, policies, and risk assessments are categorized as Managerial (Administrative) controls.
Step-by-Step Solution
Key Concept
Security Control Categories (Managerial / Administrative Controls)
Estimated Time:1m 15s